Impact
The vulnerability exists in the Authentication Engine of Oracle Access Manager and permits an unauthenticated network attacker with HTTP access to create, delete or modify access to critical data, effectively granting them unauthorized control over data stored or managed by Access Manager. This results in confidentiality and integrity violations, but does not directly affect availability.
Affected Systems
The flaw is known to affect Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0, part of Oracle Fusion Middleware. Users running these releases on any platform are potentially vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 9.1 reflects a high severity, while the EPSS score of less than 1% suggests exploitation is currently rare, and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector is network over HTTP, requiring no credentials or UI interaction, enabling a remote attacker to compromise Access Manager is exploitable with minimal effort and no prerequisites beyond network connectivity.
OpenCVE Enrichment